Malware

About “Win32/Autoit.NNF” infection

Malware Removal

The Win32/Autoit.NNF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Autoit.NNF virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
mixseo.net
bn.wshare.in
www.bing.com

How to determine Win32/Autoit.NNF?


File Info:

crc32: C089E291
md5: 6da47f79e349c42d9fb53b620a82fdd0
name: 6DA47F79E349C42D9FB53B620A82FDD0.mlw
sha1: 72b2ea4b9e5a029f83e753fd04cd8455672c0f77
sha256: 4a10b77cdd3eb63a3aa2cc32efceaff65fa5c8cd0c47f56a958d47d67a4b3724
sha512: b2e8e053d612e81017f889d7a5e468eca5529cf7ee815a9c3d7f877f1ddfca28a80742880a89aa4a1710382d3b57b2b666906384ee8a5036d436c4afd7d4dc3d
ssdeep: 12288:ThkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNRTGMp+MsHd2qAyrrsLJ+A:ZRmJkcoQricOIQxiZY1WN0G+MsH5w+A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Win32/Autoit.NNF also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3fd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader8.27549
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46242114
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.150885
K7GWTrojan ( 0055e3fd1 )
Cybereasonmalicious.b9e5a0
CyrenW32/Autoit.YSOJ-3087
ESET-NOD32Win32/Autoit.NNF
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.AutoIt.bpv
BitDefenderTrojan.GenericKD.46242114
MicroWorld-eScanTrojan.GenericKD.46242114
Ad-AwareTrojan.GenericKD.46242114
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Yahlover.dh
FireEyeGeneric.mg.6da47f79e349c42d
EmsisoftTrojan.GenericKD.46242114 (B)
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan.Win32.AutoIt.bpv
GDataTrojan.GenericKD.46242114
Acronissuspicious
MAXmalware (ai score=89)
VBA32Trojan-Downloader.Autoit.gen
RisingTrojan.StartPage/Autoit!1.D84C (CLASSIC)
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Autoit.NNF!tr
AVGWin32:Trojan-gen

How to remove Win32/Autoit.NNF?

Win32/Autoit.NNF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment